---
title: "Searching Groups | ThreatConnect"
slug: "searching-groups"
description: "This article describes how to use the Search: Groups screen to view, search, export, delete, and analyze Groups in your ThreatConnect owners."
updated: 2026-03-01T18:39:27Z
published: 2026-03-01T18:39:27Z
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Searching Groups

## Overview

The [**Search** screen](https://knowledge.threatconnect.com/docs/searching-in-threatconnect) in ThreatConnect® provides a single location to search and browse your data. You can [search all object types](https://knowledge.threatconnect.com/docs/searching-all-object-types) in your ThreatConnect dataset using keywords or phrases, or you can browse threat intelligence data by object type and filter those data to a usable and relevant subset based on details like name/summary, object subtype, owner, and metadata such as Tags, Security Labels, and Attributes.

On the **Search: Groups**screen, you can search and filter all [Groups](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#groups) in your [ThreatConnect owners](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect) using basic search queries or using advanced search queries written in [ThreatConnect Query Language (TQL)](https://knowledge.threatconnect.com/docs/threatconnect-query-language-tql). You can also [create Groups](https://knowledge.threatconnect.com/docs/creating-groups); import Groups with the [Document Parsing](https://knowledge.threatconnect.com/docs/document-parsing-import), [Email](https://knowledge.threatconnect.com/docs/email-import), and [Signature](https://knowledge.threatconnect.com/docs/signature-import) import features; export Group data to a CSV file; delete Groups individually or in bulk; and further investigate Groups that are of interest to you.

## Before You Start

### User Roles

- To view, search, and export Groups in an Organization, your user account can have any [Organization role](https://knowledge.threatconnect.com/docs/organization-roles).
- To view, search, and export Groups in a Community or Source, your user account must have a [Community role](https://knowledge.threatconnect.com/docs/community-roles) of User, Commenter, Contributor, Editor, or Director for that Community or Source.
- To delete Groups in an Organization, your user account must have an Organization role of Standard User, Sharing User, Organization Administrator, or App Developer.
- To delete Groups in a Community or Source, your user account must have a Community role of Editor or Director for that Community or Source.

## Viewing All Groups

When you first open the **Search: Groups**screen, it displays a table listing all Groups in your ThreatConnect owners. You can access the **Search: Groups**screen by selecting **Groups**from the **Search & Create**dropdown on the top navigation bar or by selecting the **Groups**filter in the left sidebar of the **Search**screen.

To view more details about a Group, do one of the following:

- Click the Group’s table row, or click the Group’s [**Options ⋯** menu](/docs/searching-groups#group-options) and select **View Details**, to open the Group’s [**Details**drawer](https://knowledge.threatconnect.com/docs/the-details-drawer).
- Click the Group’s name/summary to open the Group’s [**Details**screen](https://knowledge.threatconnect.com/docs/the-details-screen).

HintYou can adjust the columns displayed in the table on the **Search: Groups**screen by clicking **Select columns![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Select%20columns%20button.png)**in the upper right, selecting the columns to display, and clicking **Apply**.

## Searching and Filtering Groups

On the **Search: Groups**screen, you can search and filter Groups in your ThreatConnect owners by running the following types of searches:

- [Basic search](/docs/searching-groups#running-basic-searches)
- [Advanced search](/docs/searching-groups#running-advanced-searches)
- [Search using a saved query](/docs/searching-groups#running-searches-using-saved-queries)

To remove all filters and search criteria applied on the **Search: Groups**screen, click **Clear all filters & search![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Clear%20all%20filters%20&amp;%20search%20button.png)**in the upper right.

### Running Basic Searches

A basic search lets you search Groups using the search bar and various filter options on the **Search: Groups**screen. Follow these steps to run a basic search of Groups on the **Search: Groups**screen:

1. From the **Search & Create**dropdown on the top navigation bar, select **Groups**.
2. Configure a basic search query by doing the following:
  - Enter text into the search bar to [search Groups by name/summary](/docs/searching-groups#searching-by-namesummary). To run a [contains search](/docs/searching-groups#contains-search), leave the **Exact Match**checkbox cleared. To run an [exact match search](/docs/searching-groups#exact-match-search), select the **Exact Match**checkbox.
  - Use the Group type dropdown, owner dropdown, and **Filters![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Filters%20button_Details%20screen.png)**menu to [filter Groups](/docs/searching-groups#filtering-groups) by type, owner, and Group metadata, respectively.

As you configure a basic search query, the results table updates automatically based on the current search criteria.

#### Searching by Name/Summary

When searching Groups by name/summary on the **Search: Groups**screen, you can run two types of searches: [contains](/docs/searching-groups#contains-search) and [exact match](/docs/searching-groups#exact-match-search).

NoteName/summary searches are case insensitive.

##### Contains Search

A contains search lets you filter Groups based on whether their name/summary contains the text entered into the search bar on the **Search: Groups**screen. Use a contains search when you want to filter your dataset to find Groups that relate to a common keyword or phrase. Table 1 describes the search result behavior of a contains search for **volt typhoon**.

| Group Name/Summary | Returned as Result? |
| --- | --- |
| VOLT TYPHOON | Yes, because the name/summary contains the entire phrase **volt typhoon**. |
| Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure | Yes, because the name/summary contains the entire phrase **volt typhoon**. |
| Volt | No. Although the name/summary contains **volt**, it does not contain**typhoon**. |
| Typhoon Volt | No. Although the name/summary contains **volt**and **typhoon**, they are not in the same order as the phrase **volt typhoon**. |

To run a contains search on the **Search: Groups**screen, enter text into the search bar and leave the **Exact Match**checkbox cleared.

##### Exact Match Search

An exact match search lets you filter Groups based on whether their name/summary is an exact match to the text entered into the search bar on the **Search: Groups**screen. Use an exact match search when you want to search a large dataset for a specific object, as this type of search yields a more targeted set of search results. Table 2 describes the search result behavior of an exact match search for **volt typhoon**.

| Group Name/Summary | Returned as Result? |
| --- | --- |
| VOLT TYPHOON | Yes, because the name/summary is an exact match to the phrase **volt typhoon**. |
| Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure | No, because the name/summary is not an exact match to the phrase **volt typhoon**. |
| Volt | No, because the name/summary is not an exact match to the phrase **volt typhoon**. |
| Typhoon Volt | No. Although the name/summary contains **volt**and **typhoon**, they are not in the same order as the phrase **volt typhoon**. |

To run an exact match search on the **Search: Groups**screen, enter text into the search bar and select the **Exact Match**checkbox to the right of the search bar or surround the phrase in straight quotes.

ImportantThe search engine does not recognize smart quotes (`“”`). If you copied a search phrase from an application and pasted it into the search bar, replace all smart quotes with straight quotes (`"`) before running your search.

#### Filtering Groups

The **Search: Groups**screen provides the following options for filtering Groups when running basic searches:

- The Group type dropdown next to the **Exact Match**checkbox lets you filter Groups by one or more Group types. Groups are filtered automatically as you select options from the dropdown.
- The owner dropdown next to the **Filters![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Filters%20button_Details%20screen.png)**menu lets you filter Groups by one or more owners. Groups are filtered automatically as you select options in the dropdown.
- The **Filters**![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Filters%20button_Details%20screen.png)menu lets you filter Groups by Group metadata. After selecting and configuring filters, click **Apply**. Groups may be filtered by the following metadata:
  - Tags
  - Security Labels
  - Date Added
  - Last Modified
  - Attributes (**+ Add Filter** option at the lower left of the **Filters**![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Filters%20button_Details%20screen.png)menu)
  - Document Type (when viewing only Document Groups)
  - Email Score (when viewing only Email Groups)
  - Event Status (when viewing only Event Groups or only Incident Groups)
  - Event Date (when viewing only Event Groups)
  - Event Type (when viewing only Event Groups)
  - Incident Status (when viewing only Incident Groups)
  - Report Type (when viewing only Report Groups)
  - Publish Date (when viewing only Report Groups)
  - Format Type (when viewing only Signature Groups)
  - Only show My Tasks (when viewing only Task Groups)
  - Task Status (when viewing only Task Groups)
  - Task Due Date (when viewing only Task Groups)

NoteThe **Only show My Tasks**, **Task Status**, and **Task Due Date**filters apply to the [legacy Task Group](https://knowledge.threatconnect.com/docs/en/the-threatconnect-data-model#group-types), not [Workflow Tasks](https://knowledge.threatconnect.com/docs/workflow-overview#terminology).

### Running Advanced Searches

An advanced search lets you search and filter Groups using a query written in [ThreatConnect Query Language (TQL)](https://knowledge.threatconnect.com/docs/threatconnect-query-language-tql). Advanced searches enable you to perform highly targeted searches of Groups using criteria that cannot be defined when running basic searches.

Follow these steps to run an advanced search of Groups on the **Search: Groups**screen:

1. From the **Search & Create**dropdown on the top navigation bar, select **Groups**.
2. Turn on the **Advanced Search**toggle above the search bar.
3. Enter a [TQL query](https://knowledge.threatconnect.com/docs/constructing-query-expressions) into the search bar. If you configured a basic search query before turning on the **Advanced Search**toggle, the query will be converted into a TQL query and populated in the search bar automatically.NoteIf you configured Attribute filters in a basic search query, the converted advanced search query will use the Attribute Type’s name in the `attribute` parameter by default (e.g., `attributeAdversary_Type`). However, if the Attribute Type’s name contains characters other than letters, numbers, and spaces, the advanced search query will use the Attribute Type’s ID number instead of its name in the `attribute` parameter (e.g., `attribute123`). For more information on the `attribute` parameter, see the [“Query for Attributes” section in *Constructing Query Expressions*](https://knowledge.threatconnect.com/docs/constructing-query-expressions#query-for-attributes).HintYou can use the [TQL Generator](https://knowledge.threatconnect.com/docs/tql-generator) to translate plain-English prompts into TQL queries.
4. Click **Search![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Search%20drawer%20icon.png)**to the right of the search bar, or press **Enter**on your keyboard, to run your search.NoteIf a TQL query is invalid, you can hover over the validator on the left side of the search bar to view the corresponding error message.NoteIf you run an advanced search using a query that matches a [saved query](https://knowledge.threatconnect.com/docs/saved-search-queries), the saved query will be selected in the **Select Saved Query…**dropdown automatically.

### Running Searches Using Saved Queries

When using the basic or advanced search features on the **Search: Groups**screen, you can run a search using a saved query. Follow these steps to use a saved query to search Groups on the **Search: Groups**screen:

1. From the **Search & Create**dropdown on the top navigation bar, select **Groups**.
2. From the **Select Saved Query…**dropdown in the upper right, select a saved query to run.

After you select a saved query, the **Advanced Search**toggle turns on and a search using the selected query runs automatically.

HintTo save basic or advanced search queries, click **Save Query**in the upper right of the **Search: Groups**screen. For more information, see [*Saved Search Queries*](https://knowledge.threatconnect.com/docs/saved-search-queries).

## Sorting Groups

You can sort Groups by any of the table columns except for the **Tags**column. By default, Groups are sorted by the **Last Modified**column in descending order.

## Exporting Groups

The **Search: Groups**screen lets you export select data fields for a set of Groups to a comma-separated values (CSV) file. This is useful when you want to share information from ThreatConnect as part of a proactive cybersecurity defense strategy.

Follow these steps to export data for a set of Groups on the **Search: Groups**screen:

ImportantAll Groups in the results set will be exported, not just the Groups displayed on the current page of the results table.

1. From the **Search & Create**dropdown on the top navigation bar, select **Groups**.
2. (Optional) Run a [basic](/docs/searching-groups#running-basic-searches) or [advanced](/docs/searching-groups#running-advanced-searches) search.
3. From the **Options** **⋯**menu in the upper-right corner, select **Export…**.
4. On the **Export Group Data**window, select the data types to include in the CSV file, and then click **Export**.

After the export completes, a file named **ThreatConnectExport.csv** will download to your computer.

NoteExport processing times vary depending on the number of Groups and the amount of Group data being exported.

## Deleting Groups in Bulk

Follow these steps to delete a set of Groups in bulk on the **Search: Groups**screen:

1. From the **Search & Create**dropdown on the top navigation bar, select **Groups**.
2. (Optional) Run a [basic](/docs/searching-groups#running-basic-searches) or [advanced](/docs/searching-groups#running-advanced-searches) search.
3. From the **Options** **⋯**menu in the upper-right corner, select **Delete Returned Objects…**.
4. On the **Delete Returned Objects**window, click **Delete** to delete all Groups in the results table. If you are deleting more than 50 Groups, you must enter “delete” (without quotation marks) into the **Confirm Deletion**field before you can click **Delete**.WarningAll Groups in the results set will be deleted, not just the Groups displayed on the current page of the results table.

## Group Options

A Group’s **Options ⋯** menu provides the following options for managing and analyzing the Group:

- **Create Custom Report**: Create a [report](https://knowledge.threatconnect.com/docs/reports) for the Group [from scratch](https://knowledge.threatconnect.com/docs/creating-a-report#creating-a-report-without-using-a-report-template) or [from a Group report template](https://knowledge.threatconnect.com/docs/creating-a-report#creating-a-report-from-a-report-template). This option is available only if your user account has permission to create reports.
- **Follow**or **Unfollow**: [Follow](https://knowledge.threatconnect.com/docs/notifications-and-following#following-items) or unfollow the Group.
- **Pivot**: [Pivot](https://knowledge.threatconnect.com/docs/pivoting-on-data) from the Group to view its Indicator associations on the [**Search: Indicators** screen](https://knowledge.threatconnect.com/docs/searching-indicators).
- **View Details**: Open the Group’s [**Details**drawer](https://knowledge.threatconnect.com/docs/the-details-drawer).HintYou can also open the Group’s **Details**drawer by clicking on its table row.
- **Visual Analysis**: Select from the following options:
  - **Threat Graph**: Open [Threat Graph](https://knowledge.threatconnect.com/docs/threat-graph) to visualize, explore, and analyze the Group’s associations.
  - **Visualize ATT&CK**: Open the [ATT&CK Visualizer](https://knowledge.threatconnect.com/docs/attack-visualizer) and create a [standard ATT&CK view](https://knowledge.threatconnect.com/docs/standard-attack-views) with the Group added as an analysis layer.
- **Delete**: Delete the Group from its owner. This option is available only if your user account has permission to delete Groups in the Group’s owner.

---

*ThreatConnect® is a registered trademark of ThreatConnect, Inc.*

20075-08 v.01.C
